CSuite Phishing Adds Endpoint Control to Mailbox Theft
ANY.RUN traced the CSuite phishing campaign across 351 sandbox submissions, and 51% came from the United States. The activity hit technology, manufacturing, government, and consulting organizations, and it split into two access paths: Microsoft 365 session theft and deployment of legitimate remote-management tools such as ScreenConnect and Action1.
The phish uses ordinary business lures, then either steers victims into credential or device-code capture for Microsoft 365, or drops an installer, archive, or BAT/VBS file that puts a trusted remote tool on the endpoint. Because those tools are legitimate, the attacker can look like normal IT activity while keeping remote access to the device and the account.
For Microsoft 365-heavy shops that allow remote-support or RMM software on employee laptops, this means mailbox cleanup alone may not end the incident. If the session is still valid or the remote tool is already installed, the attacker can keep operating from inside the environment and turn one phish into persistent account and endpoint access.